Vulnerabilities (CVE)

Filtered by CWE-79
Total 45383 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-48949 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of validation leads to an XSS vulnerability in the MFA management views.
CVE-2026-48950 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.
CVE-2026-48951 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
CVE-2026-48952 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.
CVE-2026-48953 1 Joomla 1 Joomla\! 2026-07-09 N/A 6.1 MEDIUM
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
CVE-2025-8591 1 Wso2 8 Api Control Plane, Api Manager, Identity Server and 5 more 2026-07-09 N/A 6.1 MEDIUM
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking.
CVE-2026-8315 2026-07-09 N/A 5.4 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVE-2026-8310 2026-07-09 N/A 6.1 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
CVE-2026-56809 2026-07-09 N/A 6.1 MEDIUM
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.
CVE-2024-37859 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.
CVE-2024-37856 1 Oretnom23 1 Lost And Found Information System 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.
CVE-2024-37675 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the parameter "sectionContent" related to the functionality of adding notes to an uploaded file.
CVE-2024-37674 1 Moodle 1 Moodle 2026-07-09 N/A 5.5 MEDIUM
Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.
CVE-2024-37673 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the filename parameter.
CVE-2024-37672 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.
CVE-2024-37671 1 Tessi 1 Docubase 2026-07-09 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.
CVE-2024-32409 1 Sem-cms 1 Semcms 2026-07-09 N/A 7.1 HIGH
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
CVE-2024-32206 1 Wuzhicms 1 Wuzhicms 2026-07-09 N/A 4.6 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the component \affiche\admin\index.php of WUZHICMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $formdata parameter.
CVE-2024-31064 1 Munyweki 1 Insurance Management System 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.
CVE-2024-29644 1 Dcatadmin 1 Dcat Admin 2026-07-09 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in dcat-admin v.2.1.3 and before allows a remote attacker to execute arbitrary code via a crafted script to the user login box.